CVE-2023-43733: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "companyaddress" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Os Commerce vulnerability?
The vulnerability ID for this Os Commerce vulnerability is CVE-2023-43733.
Is Os Commerce susceptible to a Cross-Site Scripting (XSS) vulnerability?
Yes, Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting JS through the 'company_address' parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
What is the severity of CVE-2023-43733?
The severity of CVE-2023-43733 is high with a CVSS score of 5.4.
How can I fix the Cross-Site Scripting (XSS) vulnerability in Os Commerce?
To fix the Cross-Site Scripting (XSS) vulnerability in Os Commerce, it is recommended to apply the latest security patches and updates provided by Oscommerce.